VYPR
Vendor

Nagvis

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2024-13723HigFeb 4, 2025
    risk 0.47cvss 7.2epss 0.01

    The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

  • CVE-2017-6393MedMar 2, 2017
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

  • CVE-2025-39665Dec 3, 2025
    risk 0.00cvss epss 0.00

    User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

  • CVE-2024-47090May 27, 2025
    risk 0.00cvss epss 0.00

    Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

  • CVE-2024-38866May 27, 2025
    risk 0.00cvss epss 0.00

    Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection